What is CVE-2026-51252?
CVE-2026-51252 is a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function of schreibfaul1 ESP32-audioI2S version 3.4.5, caused by missing input validation on attacker-controlled MP3 metadata. This flaw could allow attackers to execute arbitrary code via maliciously crafted files. Users are advised to update the library and avoid untrusted MP3 inputs.
Azərbaycanca: CVE-2026-51252, schreibfaul1 ESP32-audioI2S kitabxanasının 3.4.5 versiyasında MP3Decoder::UnpackSFMPEG1 funksiyasında aşkarlanan buffer overflow zəifliyidir. Zəiflik MP3 metadata-nın düzgün yoxlanılmaması səbəbindən baş verir və təcavüzkara xüsusi hazırlanmış fayllar vasitəsilə sistemi ələ keçirməyə imkan verə bilər. İstifadəçilərə kitabxananı yeniləmək və şübhəli MP3 fayllarından qaçınmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which library was CVE-2026-51252 discovered?
The vulnerability was discovered in version 3.4.5 of the schreibfaul1 ESP32-audioI2S library.
What causes this buffer overflow vulnerability?
The vulnerability occurs due to missing input validation on MP3 metadata in the MP3Decoder::UnpackSFMPEG1 function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.